
Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program Security & Risk Analysis
wordpress.org/plugins/gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerceLoyalty + Referral + Rewards + Birthdays and Anniversaries + Giveaways + Contests + Competitions + Sweepstakes. Selling on ETSY? Reward points for yo …
Is Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program Safe to Use in 2026?
Generally Safe
Score 100/100Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce" plugin exhibits a mixed security posture. On the positive side, it makes good use of prepared statements for SQL queries and has a relatively high percentage of properly escaped output. The absence of critical or high-severity vulnerabilities in its history and static analysis is also a good sign. However, a significant concern arises from its attack surface, with a substantial number of unprotected AJAX handlers and REST API routes. This suggests potential entry points for unauthorized access or manipulation if further security checks are absent or bypassed.
The taint analysis reveals two high-severity flows with unsanitized paths, which is a notable risk. While the plugin has a history of a medium-severity Cross-Site Scripting (XSS) vulnerability, the fact that it is currently unpatched is a significant concern. This history, combined with the identified high-severity taint flows, indicates a recurring pattern of input sanitization weaknesses that require immediate attention. Despite the use of prepared statements and some proper output escaping, the extensive unprotected entry points and the existing medium XSS vulnerability point to areas where robust security practices are not consistently applied, warranting careful consideration and remediation.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- High severity taint flows
- Medium severity CVE, currently unpatched
- Flows with unsanitized paths
Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Gratisfaction <= 4.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program Release Timeline
Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program Attack Surface
AJAX Handlers 10
REST API Routes 26
Shortcodes 3
WordPress Hooks 60
Maintenance & Trust
Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program Maintenance & Trust
Maintenance Signals
Community Trust
Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program Alternatives
Gratisfaction- Contests Giveaways Referral Loyalty Rewards and Birthdays Program
gratisfaction-social-contests-referral-loyalty-rewards-program-by-appsmav
All-in-One Loyalty + Giveaways + Contests + Competitions + Referral + Birthdays + Anniversaries App. No Coding. Easy DIY Setup.
Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more
social-boost
Run viral giveaways, contests, competitions, sweepstakes, purchase for chance to win, instant wins, refer-a-friend, and boost subscribers, followers, …
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers
rafflepress
The best WordPress giveaway plugin. Grow your email list, website traffic, and social media followers with viral contests, giveaways, and sweepstakes.
Woobox
woobox
Easily embed your Woobox promotions in WordPress using a simple shortcode.
Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more
scratch-win-giveaways-for-website-facebook
Display a Scratch Card on your website to offer visitors a chance to win prizes. A fun incentive to boost conversions!
Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program Developer Profile
4 plugins · 1K total installs
How We Detect Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce/assets/css/gr-styles.css/wp-content/plugins/gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce/assets/css/gr-frontend.css/wp-content/plugins/gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce/assets/js/gr-frontend.js/wp-content/plugins/gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce/assets/js/gr-apply-coupon.js//cdn.appsmav.com/gr/assets/js/gr-widget-sdk.js/wp-content/plugins/gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce/assets/css/gr-styles.css?ver=/wp-content/plugins/gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce/assets/css/gr-frontend.css?ver=/wp-content/plugins/gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce/assets/js/gr-frontend.js?ver=/wp-content/plugins/gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce/assets/js/gr-apply-coupon.js?ver=HTML / DOM Fingerprints
gratisfaction-logogr-loyalty-pointsgr-points-formgr-redeem-pointsgr-referral-program-containergr-giveaway-form<!-- Appsmav Logo<!-- START WOOC ISRM CODE<!-- END WOOC ISRM CODE<!-- START WOOC GR REFERRAL CODE+3 moredata-gr-widget-endpointdata-gr-app-iddata-gr-plugin-versiondata-gr-user-iddata-gr-product-idgr_varsGratisfactionWidget/wp-json/gr-api/v1/get-points/wp-json/gr-api/v1/apply-discount/wp-json/gr-api/v1/redeem-points/wp-json/gr-api/v1/referral-data/wp-json/gr-api/v1/giveaway-entry[gr_loyalty_points][gr_referral_program][gr_giveaway][gr_rewards_history]